Privacy Policy

How VirtualBackroom.ai collects, uses, and protects your information

Last updated: June 2026

Who We Are

VirtualBackroom.ai is operated by Koala Tea with Neel LLC (doing business as Koalat.ai). We act as the data controller for the account and service data described in this policy (such as your name, email, organization, billing, and usage records). For content you submit into the Service for analysis, we generally act as a processor on your behalf; business customers' processing of that content is governed by our Data Processing Agreement. In short: we are the controller of your account and service data, and a processor of the regulatory content you submit for analysis.

Koala Tea with Neel LLC (dba Koalat.ai)
2520 Wolfe Drive, Woodridge, IL 60517, United States
Privacy contact: neel@qms.coach

1. Information We Collect

CategoryExamples
Account dataName, email, organization, authentication identifiers
Content you submitDocuments, assessment inputs, and prompts you provide for analysis
Usage dataFeature usage, AI-scan counts, timestamps, and audit-trail records
Billing dataSubscription tier and status (payment details handled by Stripe)
Technical dataIP address, browser type, and log/diagnostic information

2. How We Use Your Information

  • To provide, operate, and improve the Service and its AI features.
  • To authenticate you and maintain account security.
  • To process subscriptions and billing through our payment processor.
  • To maintain ALCOA+ audit trails for compliance traceability of AI output.
  • To enforce usage limits (such as monthly AI-scan allowances) and prevent abuse.
  • To send service-related and, where permitted, product-update communications.

3. AI Processing & Data Handling

Before any prompt is sent to an AI model, we apply automated PII/PHI sanitization to strip personal and health identifiers from the text where applicable.

For AI features routed through OpenRouter (the bulk of our text generation), prompts are processed through OpenRouter, which does not train its own models and does not store prompt or response content (it keeps only request metadata such as token counts). Every OpenRouter-routed request is configured to route only to model providers that do not use your data to train models and do not collect it for that purpose.

A small number of features (voice transcription and text-to-speech, and certain fallback paths) call OpenAI or Google APIs directly. For these, your data is handled under those providers' API terms — which do not use data submitted via their APIs to train their models — rather than under the OpenRouter routing controls described above. Providers may temporarily retain data for abuse monitoring per their own policies.

We do not sell prompt content, and we do not use customer prompts to train models. For full detail on providers and protections, see our Security & Privacy page and our AI Boundaries page.

4. Sharing & Service Providers

We never sell your data. We do not monetize or share your regulatory information except as needed to provide the Service.

We share limited data with vetted service providers ("sub-processors") who act on our behalf. Our current sub-processors are:

  • OpenRouter — routing prompts to AI model providers to generate AI output (United States).
  • OpenAI / Google — direct AI provider APIs used for voice transcription, text-to-speech, and certain fallback features (United States).
  • Microsoft — single sign-on (Microsoft / Azure AD) for users who sign in with a Microsoft account (United States).
  • Google Firebase — authentication (Google and Microsoft sign-in) and related identity services (United States).
  • Replit — application hosting, sign-in (Replit Auth), and managed database infrastructure (United States).
  • Stripe — subscription billing and payment processing (United States).
  • Resend — transactional and alert email delivery (United States).
  • VirusTotal — scanning uploaded files for malware (United States).

Business customers can request our Data Processing Agreement (DPA), which lists current sub-processors and the safeguards applied. For transfers of personal data outside your region (including to the United States), we rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) and, for UK data, the UK International Data Transfer Addendum (IDTA), as set out in the DPA. [ Applicability of each mechanism to specific data flows to be confirmed with counsel. ]

We may also disclose information where required by law or to protect rights and safety.

5. Retention & Security

  • We retain account and content data while your account is active. When you close your account, we erase your personal identifiers immediately and apply the retention windows below.
  • Personal data (closed accounts): identifiers are scrubbed at closure; any residual account record is retained no longer than 90 days.
  • Content you submitted (e.g., documents): deleted within 30 days of account closure, unless still required for a record we must retain.
  • Compliance AI audit-trail records: retained for 24 months to support regulatory traceability, then purged.
  • Billing records: retained for approximately 7 years to meet tax and accounting obligations (held by our payment processor).
  • Technical/operational logs: typically retained 30–90 days.
  • Data is encrypted in transit (TLS 1.2+) and stored on secure infrastructure with encrypted credentials.
  • We apply access controls, authentication, and abuse monitoring to protect your data.

6. Your Rights & Choices

Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to:

  • Access, correct, or delete your personal data.
  • Export your data for your records or auditing purposes.
  • Object to or restrict certain processing, and withdraw consent where applicable.
  • Lodge a complaint with a supervisory authority.

Signed-in users can export a portable copy of their data and delete their account (which erases personal data) directly from Account Settings.

You can also exercise these rights by contacting us at neel@qms.coach; we will respond consistent with applicable law. [ Jurisdiction-specific verification and response timelines to be confirmed with counsel. ]

7. Cookies & Tracking

We use only cookies and similar technologies that are strictly necessary for the Service to function — including authentication, session management, and security (such as CSRF protection). These do not require consent under most frameworks.

We do not use advertising cookies, third-party analytics, or cross-site tracking, and we do not use cookies to sell your data.

8. Children & Changes to This Policy

  • Children. The Service is intended for business/professional use and is not directed to children under 16.
  • Changes. We may update this policy; material changes will be posted on this page with a revised "Last updated" date.

Privacy Questions?

Contact us with any questions or to exercise your privacy rights.

Koala Tea with Neel LLC (dba Koalat.ai)
2520 Wolfe Drive, Woodridge, IL 60517, United States
neel@qms.coach

Contact Us